2. The legal basis for the processing of personal data by CUTBYFRED
In accordance with personal data protection regulations, each processing operation carried out by CUTBYFRED is undertaken on an appropriate legal basis.
Accordingly, most of the processing relating to the order placed by the customer on the CUTBYFRED website has as its legal basis the performance of the contract between CUTBYFRED and the customer (orders, delivery, after-sales service, etc., as well as the other purposes detailed below).
The processing of the customer's personal data may also be necessary to comply with a legal obligation to which CUTBYFRED is subject, for example accounting and tax obligations (invoice records, etc., as well as the other purposes detailed below).
Some processing of personal data is carried out with the consent of the customer and/or Internet user, such as the distribution of newsletters.
In the event of processing based on the legitimate interests of CUTBYFRED or a third party (for example for the management of pre-litigation and litigation, etc., as well as the other purposes detailed below), CUTBYFRED will ensure that the processing in question is in fact necessary to protect its legitimate interests and will assess the consequences of this processing for the data subject, in particular by taking into account the nature of the processed personal data and the way in which it is processed.
3. The purposes of the data processing carried out by CUTBYFRED
CUTBYFRED processes personal data from its website for the following purposes:
carrying out customer management operations relating to product orders:
- deliveries; invoices; accounting and, in particular, accounts receivable management;
- booking salon appointments directly on the CUTBYFRED website;
- monitoring customer relations, such as conducting satisfaction surveys, managing complaints and the after-sales service;
- selecting customers for research, surveys and product testing.
carrying out canvassing operations:
- managing technical prospecting operations (including technical operations such as standardisation, enrichment and deduplication);
- selecting people for loyalty programmes, canvassing, surveys, product testing and promotional activities;
- carrying out solicitation operations.
- compiling commercial statistics;
- organising giveaways, lotteries or any other promotional initiatives, with the exception of online gambling, which is subject to approval by the French online gambling authorities (Autorité de Régulation des Jeux en Ligne);
- managing requests to exercise the rights set out in Article 8 below;
- managing unpaid bills and disputes and combating fraud;
- managing reviews of CUTBYFRED products, whether on the CUTBYFRED website or on other websites, in particular social networks.
4. Storage of personal data
The https://cutbyfred.com/ website and the personal data of customers and Internet users collected from it are hosted by OVH, whose contact details can be found at the following link https://cutbyfred.com/mentions-legales/.
Every precaution has been taken to have customers' and Internet users' personal data stored in a secure environment and to prevent it from being distorted, damaged or accessed by unauthorised third parties. Information sent by customers and Internet users will never be passed on to third parties for commercial purposes, nor will it be sold or exchanged.
5. The collection of personal data from Internet users and customers by CUTBYFRED
CUTBYFRED processes the following personal data of Internet users and customers from the CUTBYFRED website:
a) identity: title, surname, first names, delivery and billing address, telephone number, e-mail addresses, internal processing code enabling the customer to be identified
b) data relating to transactions, such as transaction number and purchase details. Please note that CUTBYFRED uses two payment service providers for payment purposes: i) Mollie, whose confidentiality policy can be accessed by clicking here" and ii) Paypal, whose confidentiality policy can be accessed by clicking here. CUTBYFRED does not therefore retain any credit card numbers. Customers are invited to contact Mollie and Paypal directly if they have any questions on this subject;"
c) data relating to monitoring commercial relationship: requests for documentation, trial requests, purchased product, quantity, amount, delivery address, purchase and service history (e.g., trade show appointments), product returns, correspondence with the customer and after-sales service, exchanges and reviews from customers and prospective customers
d) data relating to invoice payments: terms of payment, discounts granted, receipts, balances and unpaid amounts
e) the data required to carry out loyalty-building, canvassing, research, surveys, product testing and promotional activities"
f) data relating to organising and processing giveaways, lotteries and any promotional activities, such as the date of participation, the answers given to giveaway quizzes and the nature of the prizes offered"
g) data relating to the contributions of persons who post reviews on products, services or content, in particular their pseudonym.
6. Length of storage of customers’ and prospective customers’ personal data
Personal data relating to an order is kept in the active database for a period of three (3) years from the end of the commercial relationship.
Personal data relating to a prospective customer (for example, an Internet user who has not placed an order but has created an account or subscribed to the newsletter) is kept for a period of three (3) years from the date on which it is collected by CUTBYFRED or from the last contact from the prospective customer (for example, a request for documentation or a click on a hyperlink text contained in an e-mail).
Personal data is then kept in intermediate storage for a period that does not exceed the purpose of the storage (invoices are stored for ten (10) years, data required in order to prove a right and/or obligation is stored for the duration of the relevant statute of limitations, etc.).
7. Recipients or categories of recipients of customers' and Internet users' personal data
The personal data of customers and Internet users is processed by authorised CUTBYFRED personnel for the purposes set out above.
The personal data of customers and Internet users may be communicated to service providers such as :
- the hosting and maintenance service providers for the https://cutbyfred.com/ website;
- logistics and transport service providers;
- providers of marketing and management solutions for sales canvassing and communication via social networks;
- customer service providers;
Where applicable, any transfer of CUTBYFRED's customers’ and/or Internet users’ personal data outside the European Economic Area will be carried out by CUTBYFRED subject to appropriate guarantees, in particular contractual guarantees via standard contractual, technical and organisational clauses, in compliance with the French Data Protection Act and the GDPR.
8. The rights of CUTBYFRED customers and Internet users
In accordance with the Data Protection Act and the GDPR, customers and Internet users whose personal data is processed by CUTBYFRED from the https://cutbyfred.com/ website may, at any time, benefit from the rights of access, rectification, deletion, limitation of processing, portability, opposition and withdrawal of their consent to the processing of their data for a specific purpose (when the processing is subject to such consent), as well as from the right not to be the subject of an automated decision and from the post-mortem right to privacy.
These rights may be exercised at any time:
- by e-mail at the following address: firstname.lastname@example.org ;
- by post to the following address Cut By Fred, 68 rue d’Hauteville 75010 Paris
A reply will be sent to the applicant within a maximum of one (1) month from the date of receipt of the request.
If necessary, this period may be extended by two (2) months by CUTBYFRED, depending on the complexity and/or number of requests. CUTBYFRED will then notify the applicant of this extension.
In the event that the customer or Internet user requests the deletion of their personal data and/or in the event that they exercise their right to request the deletion of their personal data, CUTBYFRED may, however, continue to store the data in intermediate archiving for the period required by its legal obligations, or for the purpose of proof during the applicable limitation period.
Applicants may also lodge a complaint with the competent supervisory authority, the CNIL, at www.cnil.fr.)
CUTBYFRED's website and business activities may be subject to change, for example in the event of a change in commercial policy or new technological options.
As a result, CUTBYFRED may amend this Confidentiality Policy. CUTBYFRED reserves the right to update and amend it at any time and without providing a reason.
Where applicable, if customers have a customer account, they will be notified of this change by e-mail.
In any event, CUTBYFRED invites customers and/or Internet users to consult this policy regularly, and more particularly before providing personal data.
Continued use of the CUTBYFRED website after the changes made to this Confidentiality Policy are applied constitutes acceptance of the provisions of the revised Policy, in the form in which it now applies.